National Vulnerability Database

National Vulnerability Database

CVE-2018-17654 Detail

Current Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the insertInstance method of a Form object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6504.

Analysis Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the insertInstance method of a Form object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6504.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.

Change History

Initial Analysis -
1/24/2019 10:15:57 AM

Action

Type

Old Value

New Value

Added

CPE Configuration

AND
OR
*cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* versions up to (including) 9.2.0.9297
*cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* versions up to (including) 9.2.0.9297
OR
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*